Re: no daemons listening and errata updates (secure or not?)



I assume as you are applying updates that you are using Fedora Core 5.
Just check that the firewall and SElinux are enabled, System /
Administration / Security Level and Firewall.


On Fri, 2006-07-28 at 22:51 +0800, Michael Boman wrote:
On 7/28/06, sun sadm <sunsadm@xxxxxxxxx> wrote:
Hi colleague

I am using Fedora Core as workstation. To lock down the OS, I disable
all network daemons: only dhclient is listening for network
connections. Furthermore I regularly update my installation using yum.
All other setting are out-of-the-box from Red Hat.

Is my simple setup secure to be connected directly to the Internet?
Does an attacker have a chance to break my workstation? How high is
the risk? What can I do to improve the security? How would you break
in my system? Please show me vulnerabilites in my setup.

Nico

There is always a risk of being compromised, but you are doing good
progress. I would put up an iptables firewall to make sure that no
errant network service accidentally being enabled would compromise
your security (you could investigate blocking outbound traffic too, if
you are really paranoid). The rest is basically behavior: only run
software that comes from good sources, beware of strangers etc....

If there is no service to break in to (and there is no nasty kernel
bug you can exploit), the only way to get in to your system would be
tricking you to open it up in one way or another (browser/email
client/other software you use exploits, get you to install trojaned
software etc...).

Best regards
Michael Boman


---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • [REVS] Bypassing Client Application Protection Techniques
    ... Get your security news from a reliable source. ... protection programs. ... * Kerio Personal Firewall 4.0 ... And we got actually nothing in the field of client application ...
    (Securiteam)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re:RE : suggestions on a good firewall
    ... Subject: RE: suggestions on a good firewall ... CheckPoint does! ... with a url-filtering server. ... IT Technical Security Officer ...
    (Security-Basics)
  • Why hasnt Symantec addressed nastier Messenger spoofs
    ... Norton / Symantec has been silent on whether Norton Internet Security ... DSL firewall will stop these kinds of pop-ups. ... major ISPs and broadband systems. ...
    (comp.security.misc)
  • Re: Service pack 2 (XP)
    ... I have a 'theory' that SP2 has a LOT to do with firewall and new browser ... besides those security features. ... The operative word is SPYWARE. ...
    (microsoft.public.windowsupdate)